monstra records
43 published records for vendor monstra.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.3%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-434 Unrestricted Upload of File with Dangerous Type9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-384 Session Fixation2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
43 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2017-18048Weaponized | Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lmonstra · monstra · CWE-434 | High8.8 | — | 63.4% | Jan 23, 2018 |
40Plan | CVE-2021-36548No exploit | A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4monstra · monstra · CWE-434 | Critical9.8 | — | 3.3% | Oct 28, 2021 |
40Plan | CVE-2020-25414No exploit | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrmonstra · monstra · CWE-829 | Critical9.8 | — | 2.0% | Jun 17, 2021 |
40Plan | CVE-2018-11678No exploit | plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.monstra · monstra cms · CWE-20 | Critical9.8 | — | 1.7% | Jun 5, 2018 |
39Monitor | CVE-2018-6383Proof of concept | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phamonstra · monstra · CWE-184 | High8.8 | — | 13.5% | Jan 29, 2018 |
39Monitor | CVE-2021-40940No exploit | Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.monstra · monstra · CWE-434 | Critical9.8 | — | 1.6% | Jun 15, 2022 |
36Monitor | CVE-2018-9037No exploit | Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain monstra · monstra · CWE-434 | High8.8 | — | 2.8% | Apr 10, 2018 |
36Monitor | CVE-2020-13384No exploit | Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fomonstra · monstra · CWE-434 | High8.8 | — | 2.5% | May 22, 2020 |
35Monitor | CVE-2020-23219No exploit | Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit monstra · monstra cms · CWE-94 | High8.8 | — | 1.6% | Jul 1, 2021 |
35Monitor | CVE-2018-16608No exploit | In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&actimonstra · monstra · CWE-639 | High8.8 | — | 1.2% | Sep 10, 2018 |
35Monitor | CVE-2025-69906Proof of concept | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.monstra · monstra cms · CWE-434 | High8.8 | — | 0.7% | Feb 5, 2026 |
32Monitor | CVE-2018-11474No exploit | Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.monstra · monstra · CWE-384 | High8.0 | — | 1.1% | May 25, 2018 |
32Monitor | CVE-2018-11475No exploit | Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.monstra · monstra · CWE-384 | High8.0 | — | 1.1% | May 25, 2018 |
31Monitor | CVE-2018-16820No exploit | admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.monstra · monstra · CWE-22 | High7.5 | — | 2.0% | Sep 18, 2018 |
29Monitor | CVE-2018-9038Proof of concept | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.monstra · monstra · CWE-22 | Medium6.5 | — | 9.3% | Apr 10, 2018 |
29Monitor | CVE-2018-17418Proof of concept | Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filemonstra · monstra · CWE-434 | High7.2 | — | 3.1% | Mar 7, 2019 |
28Monitor | CVE-2018-15886No exploit | Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippemonstra · monstra · CWE-94 | High7.2 | — | 1.6% | Sep 10, 2018 |
28Monitor | CVE-2020-13978No exploit | Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute monstra · monstra cms · CWE-78 | High7.2 | — | 1.3% | Jun 9, 2020 |
28Monitor | CVE-2024-36774No exploit | An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.monstra · monstra · CWE-434 | High7.2 | — | 0.7% | Jun 6, 2024 |
26Monitor | CVE-2020-8439No exploit | Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit Umonstra · monstra · CWE-425 | Medium6.5 | — | 1.6% | Mar 6, 2020 |
26Monitor | CVE-2020-20691No exploit | An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadimonstra · monstra cms · CWE-434 | Medium6.5 | — | 0.9% | Sep 27, 2021 |
25Monitor | CVE-2018-11227Proof of concept | Monstra CMS 3.0.4 and earlier has XSS via index.php.monstra · monstra cms · CWE-79 | Medium6.1 | — | 4.7% | Jul 3, 2019 |
25Monitor | CVE-2018-16979Proof of concept | Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294monstra · monstra · CWE-113 | Medium6.1 | — | 3.0% | Sep 12, 2018 |
25Monitor | CVE-2018-11473Proof of concept | Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).monstra · monstra · CWE-79 | Medium6.1 | — | 2.3% | May 25, 2018 |
25Monitor | CVE-2018-14922No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via tmonstra · monstra · CWE-79 | Medium6.1 | — | 2.0% | Aug 14, 2018 |
- CVE-2017-1804854Plan
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (l
HighCVSS 8.8WeaponizedEPSS 63%monstra · monstraJan 23, 2018
- CVE-2021-3654840Plan
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4
CriticalCVSS 9.8No exploitEPSS 3%monstra · monstraOct 28, 2021
- CVE-2020-2541440Plan
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitr
CriticalCVSS 9.8No exploitEPSS 2%monstra · monstraJun 17, 2021
- CVE-2018-1167840Plan
plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.
CriticalCVSS 9.8No exploitEPSS 2%monstra · monstra cmsJun 5, 2018
- CVE-2018-638339Monitor
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha
HighCVSS 8.8Proof of conceptEPSS 13%monstra · monstraJan 29, 2018
- CVE-2021-4094039Monitor
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%monstra · monstraJun 15, 2022
- CVE-2018-903736Monitor
Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain
HighCVSS 8.8No exploitEPSS 3%monstra · monstraApr 10, 2018
- CVE-2020-1338436Monitor
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fo
HighCVSS 8.8No exploitEPSS 3%monstra · monstraMay 22, 2020
- CVE-2020-2321935Monitor
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit
HighCVSS 8.8No exploitEPSS 2%monstra · monstra cmsJul 1, 2021
- CVE-2018-1660835Monitor
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&acti
HighCVSS 8.8No exploitEPSS 1%monstra · monstraSep 10, 2018
- CVE-2025-6990635Monitor
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.
HighCVSS 8.8Proof of conceptEPSS 1%monstra · monstra cmsFeb 5, 2026
- CVE-2018-1147432Monitor
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.
HighCVSS 8.0No exploitEPSS 1%monstra · monstraMay 25, 2018
- CVE-2018-1147532Monitor
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.
HighCVSS 8.0No exploitEPSS 1%monstra · monstraMay 25, 2018
- CVE-2018-1682031Monitor
admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.
HighCVSS 7.5No exploitEPSS 2%monstra · monstraSep 18, 2018
- CVE-2018-903829Monitor
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
MediumCVSS 6.5Proof of conceptEPSS 9%monstra · monstraApr 10, 2018
- CVE-2018-1741829Monitor
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP file
HighCVSS 7.2Proof of conceptEPSS 3%monstra · monstraMar 7, 2019
- CVE-2018-1588628Monitor
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippe
HighCVSS 7.2No exploitEPSS 2%monstra · monstraSep 10, 2018
- CVE-2020-1397828Monitor
Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute
HighCVSS 7.2No exploitEPSS 1%monstra · monstra cmsJun 9, 2020
- CVE-2024-3677428Monitor
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
HighCVSS 7.2No exploitEPSS 1%monstra · monstraJun 6, 2024
- CVE-2020-843926Monitor
Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit U
MediumCVSS 6.5No exploitEPSS 2%monstra · monstraMar 6, 2020
- CVE-2020-2069126Monitor
An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadi
MediumCVSS 6.5No exploitEPSS 1%monstra · monstra cmsSep 27, 2021
- CVE-2018-1122725Monitor
Monstra CMS 3.0.4 and earlier has XSS via index.php.
MediumCVSS 6.1Proof of conceptEPSS 5%monstra · monstra cmsJul 3, 2019
- CVE-2018-1697925Monitor
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294
MediumCVSS 6.1Proof of conceptEPSS 3%monstra · monstraSep 12, 2018
- CVE-2018-1147325Monitor
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
MediumCVSS 6.1Proof of conceptEPSS 2%monstra · monstraMay 25, 2018
- CVE-2018-1492225Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via t
MediumCVSS 6.1No exploitEPSS 2%monstra · monstraAug 14, 2018